← Vulnerability feed

Vulnerability record · CVE-2018-8036 · published 3 July 2018

CVE-2018-8036: Apache pdfbox vulnerability

Apache · Pdfbox

In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.

6.5 CVSS 3.0 Medium EPSS 4.6% · top 8.6% CWE-835 · CWE-835
6.5CVSS 3.0 base score, v2 4.3
4.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-8036 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-0228Apache pdfbox xml external entity (xxe) vulnerabilityApache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attac…EPSS 9.5%7.8CVE-2016-2175Apache pdfbox vulnerabilityApache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XM…EPSS 3.8%5.5CVE-2021-31811Apache pdfbox allocation without limits vulnerabilityIn Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version …EPSS 3.4%5.5CVE-2021-31812Apache pdfbox vulnerabilityIn Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 a…EPSS 3.1%5.5CVE-2021-27807Apache pdfbox vulnerabilityA carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x ver…EPSS 3.0%5.5CVE-2021-27906Apache pdfbox vulnerabilityA carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2…EPSS 3.3%5.5CVE-2018-11797Apache pdfbox vulnerabilityIn Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing …EPSS 3.5%4.3CVE-2026-33929Apache pdfbox path traversal vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples. This issue affects the Extrac…EPSS 0.96%

Source: NIST National Vulnerability Database (record CVE-2018-8036), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.